CVE-2022-1253
published 2022-04-06CVE-2022-1253: Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.02%
78.8th percentile
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libde265 | < libde265 1.0.8-1.1 (bookworm) | libde265 1.0.8-1.1 (bookworm) |
| struktur | libde265 | <= 1.0.8 | — |
| struktur | libde265 | >= 0 < 1.0.11-0+deb11u1 | 1.0.11-0+deb11u1 |
| struktur | libde265 | >= 0 < 1.0.8-1.1 | 1.0.8-1.1 |
| struktur | libde265 | >= 0 < 1.0.8-1.1 | 1.0.8-1.1 |
| struktur | libde265 | >= 0 < 1.0.8-1.1 | 1.0.8-1.1 |
| struktur | libde265 | >= 0 < 1.0.4-1ubuntu0.2 | 1.0.4-1ubuntu0.2 |
| struktur | libde265 | >= 0 < 1.0.8-1ubuntu0.1 | 1.0.8-1ubuntu0.1 |
| struktur | libde265 | >= 0 < 1.0.2-2ubuntu0.16.04.1~esm2 | 1.0.2-2ubuntu0.16.04.1~esm2 |
| struktur | libde265 | >= 0 < 1.0.2-2ubuntu0.18.04.1~esm2 | 1.0.2-2ubuntu0.18.04.1~esm2 |
| strukturag | strukturag_libde265 | unspecified – 1.0.8 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
cisa7.8HIGH
vendor_debian9.8CRITICAL
vendor_redhat6.9MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: chardev: fix error handling in cdev_device_add()
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2022-50282 [MEDIUM] CWE-908 kernel: chardev: fix error handling in cdev_device_add()
kernel: chardev: fix error handling in cdev_device_add()
In the Linux kernel, the following vulnerability has been resolved:
chardev: fix error handling in cdev_device_add()
While doing fault injection test, I got the following report:
------------[ cut here ]------------
kobject: '(null)' (0000000039956980): is not initialized, yet kobject_put() is being called.
WARNING: CPU: 3 PID: 6306 at kobject_put+0x23d/0x4e0
CPU: 3 PID: 6306 Comm: 283 Tainted: G W 6.1.0-rc2-00005-g307c1086d7c9 #1253
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: 0010:kobject_put+0x23d/0x4e0
Call Trace:
cdev_device_add+0x15e/0x1b0
__iio_device_register+0x13b4/0x1af0 [industrialio]
__devm_iio_device_register+0x22/0x90 [industrialio]
max517_probe+0x3d8/0x6b4 [max517]
i2c
Ubuntu
libde265 vulnerabilities
vendor_ubuntu·2024-02-08·CVSS 6.5
CVE-2022-43242 [MEDIUM] libde265 vulnerabilities
Title: libde265 vulnerabilities
Summary: Several security issues were fixed in libde265.
It was discovered that libde265 could be made to read out of bounds. If a
user or automated system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to cause a denial of
service. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,
CVE-2022-43242)
It was discovered that libde265 did not properly manage memory. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 22.04 LTS.
(CVE-2021-36408)
It was discovered that libde265 contained a logical error. If a user
or automated system were trick
CISA
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
cisa·2022-03-15·CVSS 7.8
CVE-2019-1253 [HIGH] CWE-59 Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Affected: Microsoft Windows
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1253
Remediation Due Date: 2022-04-05
Debian
CVE-2022-1253: libde265 - Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and...
vendor_debian·2022·CVSS 9.8
CVE-2022-1253 [CRITICAL] CVE-2022-1253: libde265 - Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and...
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
Scope: local
bookworm: resolved (fixed in 1.0.8-1.1)
bullseye: resolved (fixed in 1.0.11-0+deb11u1)
forky: resolved (fixed in 1.0.8-1.1)
sid: resolved (fixed in 1.0.8-1.1)
trixie: resolved (fixed in 1.0.8-1.1)
Red Hat
kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls
vendor_redhat·2011-04-14·CVSS 6.9
CVE-2011-2022 [MEDIUM] kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls
kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
Statement: This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise 4, 5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0927.html, https://rhn.redhat.com/errata/RHSA-2011-1350.html, and https://rhn.redhat.com/errata/RHSA-2011-1253
OSV
libde265 vulnerabilities
osv·2024-02-08·CVSS 6.5
CVE-2021-35452 [MEDIUM] libde265 vulnerabilities
libde265 vulnerabilities
It was discovered that libde265 could be made to read out of bounds. If a
user or automated system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to cause a denial of
service. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,
CVE-2022-43242)
It was discovered that libde265 did not properly manage memory. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 22.04 LTS.
(CVE-2021-36408)
It was discovered that libde265 contained a logical error. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possi
GHSA
GHSA-232g-h7w4-2pxj: Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1
ghsa_unreviewed·2022-04-07
CVE-2022-1253 [CRITICAL] CWE-122 GHSA-232g-h7w4-2pxj: Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.
OSV
CVE-2022-1253: Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1
osv·2022-04-06·CVSS 9.8
CVE-2022-1253 [CRITICAL] CVE-2022-1253: Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
No detection rules found.
No public exploits indexed.
https://github.com/strukturag/libde265/commit/8e89fe0e175d2870c39486fdd09250b230ec10b8https://huntr.dev/bounties/1-other-strukturag/libde265https://www.debian.org/security/2023/dsa-5346https://github.com/strukturag/libde265/commit/8e89fe0e175d2870c39486fdd09250b230ec10b8https://huntr.dev/bounties/1-other-strukturag/libde265https://www.debian.org/security/2023/dsa-5346
2022-04-06
Published